refresh-token.ts 3.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293
  1. import { apiPrefix } from '@/config'
  2. import { fetchWithRetry } from '@/utils'
  3. const LOCAL_STORAGE_KEY = 'is_other_tab_refreshing'
  4. let isRefreshing = false
  5. function waitUntilTokenRefreshed() {
  6. return new Promise<void>((resolve, reject) => {
  7. function _check() {
  8. const isRefreshingSign = globalThis.localStorage.getItem(LOCAL_STORAGE_KEY)
  9. if ((isRefreshingSign && isRefreshingSign === '1') || isRefreshing) {
  10. setTimeout(() => {
  11. _check()
  12. }, 1000)
  13. }
  14. else {
  15. resolve()
  16. }
  17. }
  18. _check()
  19. })
  20. }
  21. const isRefreshingSignAvailable = function (delta: number) {
  22. const nowTime = new Date().getTime()
  23. const lastTime = globalThis.localStorage.getItem('last_refresh_time') || '0'
  24. return nowTime - parseInt(lastTime) <= delta
  25. }
  26. // only one request can send
  27. async function getNewAccessToken(timeout: number): Promise<void> {
  28. try {
  29. const isRefreshingSign = globalThis.localStorage.getItem(LOCAL_STORAGE_KEY)
  30. if ((isRefreshingSign && isRefreshingSign === '1' && isRefreshingSignAvailable(timeout)) || isRefreshing) {
  31. await waitUntilTokenRefreshed()
  32. }
  33. else {
  34. isRefreshing = true
  35. globalThis.localStorage.setItem(LOCAL_STORAGE_KEY, '1')
  36. globalThis.localStorage.setItem('last_refresh_time', new Date().getTime().toString())
  37. globalThis.addEventListener('beforeunload', releaseRefreshLock)
  38. const refresh_token = globalThis.localStorage.getItem('refresh_token')
  39. // Do not use baseFetch to refresh tokens.
  40. // If a 401 response occurs and baseFetch itself attempts to refresh the token,
  41. // it can lead to an infinite loop if the refresh attempt also returns 401.
  42. // To avoid this, handle token refresh separately in a dedicated function
  43. // that does not call baseFetch and uses a single retry mechanism.
  44. const [error, ret] = await fetchWithRetry(globalThis.fetch(`${apiPrefix}/refresh-token`, {
  45. method: 'POST',
  46. headers: {
  47. 'Content-Type': 'application/json;utf-8',
  48. },
  49. body: JSON.stringify({ refresh_token }),
  50. }))
  51. if (error) {
  52. return Promise.reject(error)
  53. }
  54. else {
  55. if (ret.status === 401)
  56. return Promise.reject(ret)
  57. const { data } = await ret.json()
  58. globalThis.localStorage.setItem('console_token', data.access_token)
  59. globalThis.localStorage.setItem('refresh_token', data.refresh_token)
  60. }
  61. }
  62. }
  63. catch (error) {
  64. console.error(error)
  65. return Promise.reject(error)
  66. }
  67. finally {
  68. releaseRefreshLock()
  69. }
  70. }
  71. function releaseRefreshLock() {
  72. if (isRefreshing) {
  73. isRefreshing = false
  74. globalThis.localStorage.removeItem(LOCAL_STORAGE_KEY)
  75. globalThis.localStorage.removeItem('last_refresh_time')
  76. globalThis.removeEventListener('beforeunload', releaseRefreshLock)
  77. }
  78. }
  79. export async function refreshAccessTokenOrRelogin(timeout: number) {
  80. return Promise.race([new Promise<void>((resolve, reject) => setTimeout(() => {
  81. releaseRefreshLock()
  82. reject(new Error('request timeout'))
  83. }, timeout)), getNewAccessToken(timeout)])
  84. }